PT-2026-52546 · Newsblur · Newsblur
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NewsBlur versions prior to 14.5.0
Description
Broken access control allows authenticated users to read private notification feeds. By supplying arbitrary
user id values to the 'GET /social/interactions' endpoint, an attacker can bypass ownership verification to access another user's follows, replies, and social activity through enumeration of user id values.Recommendations
Update to version 14.5.0 or later.
Avoid using the
user id parameter in the 'GET /social/interactions' endpoint to access data not owned by the authenticated user.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Newsblur